|
21 | 21 | - [ ] [《Java安全性编程指南》]()@庞南 |
22 | 22 | - [ ] [《Java安全》]()@奥克斯 |
23 | 23 | - [ ] [《Java编码指南》](https://www.amazon.co.uk/%E7%BC%96%E5%86%99%E5%AE%89%E5%85%A8%E5%8F%AF%E9%9D%A0%E7%A8%8B%E5%BA%8F%E7%9A%8475%E6%9D%A1%E5%BB%BA%E8%AE%AE%EF%BC%88%E8%8B%B1%E6%96%87%E7%89%88%EF%BC%89-%E5%BE%B7%E9%B2%81%C2%B7%E8%8E%AB%E6%AC%A3%E8%BE%BE%EF%BC%88Dhruv-C-%E8%A5%BF%E7%A7%91%E5%BE%B7%EF%BC%88Robert-F-%E8%90%A8%E7%91%9F%E5%85%B0%EF%BC%88Dean-%E5%BC%97%E9%9B%B7%E5%BE%B7%C2%B7%E6%9C%97%EF%BC%88Fred/dp/B017WGUFKO)@刘先宁 |
24 | | -- [ ] [《Java-Web-Security》]()@Dominik Schadow |
| 24 | +- [ ] [《Java-Web-Security》](https://play.google.com/store/books/details/Java_Web_Security_Sichere_Webanwendungen_mit_Java_?id=ZxZ4DwAAQBAJ&hl=en_US&gl=US)@Dominik Schadow |
25 | 25 |
|
26 | 26 | 二、基础教程 |
27 | 27 | - [ ] [《Java Web安全-代码审计》]()@凌天实验室 |
|
45 | 45 | - [ ] [《Java代码审计系列课程》](https://edu.51cto.com/course/27875.html)@Hack_Man |
46 | 46 | - [ ] [《Java代码审计课程》](https://www.learnfuture.com/study/ist126v)@嘉为教育 |
47 | 47 | - [ ] [《宽字节安全 JAVA安全线上进阶课程》](https://www.cnblogs.com/unicodeSec/p/15062087.html)@宽字节 |
| 48 | +- [ ] [《Securing Java Web Applications》](https://www.pluralsight.com/courses/java-web-application-security-vulnerabilities)@Josh Cummings |
48 | 49 |
|
49 | 50 | 四、培训演讲 |
50 | 51 |
|
51 | | -五、审计报告 |
| 52 | +五、专利文献 |
52 | 53 |
|
53 | | -六、其他资源 |
| 54 | +- [ ] [一种基于java的web动态安全漏洞检测方法](https://patents.google.com/patent/CN103699480B/zh)@安恒 |
| 55 | + |
| 56 | +六、审计报告 |
| 57 | + |
| 58 | +七、其他资源 |
54 | 59 | - [ ] [《攻击Java Web应用》](https://zhishihezi.net/b/5d644b6f81cbc9e40460fe7eea3c7925)@javasec |
55 | 60 | - [ ] [《J2EE 渗透测试与安全开发》](https://zhishihezi.net/b/98ae566719b21536dff0c4febaa697d2)@路人甲 |
56 | 61 | - [ ] [《静态程序分析入门教程》](https://github.com/RangerNJU/Static-Program-Analysis-Book) |
| 62 | +- [ ] [《Java代码审计文章集合》](https://www.cnblogs.com/r00tuser/p/10577571.html)@r00tuser |
57 | 63 | - [ ] https://github.com/su18/JDBC-Attack |
58 | 64 | - [ ] https://xz.aliyun.com/t/7945 |
59 | 65 | - [ ] http://tttang.com/archive/1322 |
|
67 | 73 | - [ ] https://github.com/safe6Sec/JavaDeserialization |
68 | 74 | - [ ] https://github.com/ninthDevilHAUNSTER/JavaSecLearning |
69 | 75 | - [ ] https://github.com/Ghost2097221/javaweb_security_study_notes |
70 | | -- [ ] https://github.com/Ghost2097221/javaweb_security_study_notes |
71 | 76 | - [ ] https://github.com/Cryin/JavaID |
72 | | -- [ ] [《Java代码审计文章集合》](https://www.cnblogs.com/r00tuser/p/10577571.html)@r00tuser |
| 77 | +- [ ] https://paper.seebug.org/312 |
73 | 78 |
|
74 | 79 | ## 02-Java代码审计工具 |
75 | 80 |
|
|
117 | 122 | - [ ] https://codeql.github.com |
118 | 123 | - [ ] https://github.com/cqkenuo/LingZhi |
119 | 124 | - [ ] https://github.com/blinkfox/stalker |
| 125 | +- [ ] https://github.com/spotbugs/spotbugs |
| 126 | +- [ ] https://github.com/SonarSource/sonarqube |
| 127 | +- [ ] https://www.jarchitect.com |
| 128 | +- [ ] https://checkstyle.sourceforge.io |
| 129 | +- [ ] https://github.com/eclipse/eclemma |
120 | 130 |
|
121 | 131 | ## 03-Java漏洞靶场平台 |
122 | 132 |
|
|
139 | 149 | - [ ] [JavaVulnerableLab circle-练习Java反序列化的最简单环境](https://github.com/pmiaowu/DeserializationTest)@pmiaowu |
140 | 150 | - [ ] [易受攻击的Java Web应用程序](https://github.com/Zhangyao-zzyy/JavaVulnerableLab-circle)@Zhangyao-zzyy |
141 | 151 | - [ ] https://github.com/l4yn3/micro_service_seclab |
| 152 | +- [ ] https://gitee.com/cor0ps/java-range |
142 | 153 | - [ ] https://github.com/c0ny1/xxe-lab |
143 | 154 | - [ ] https://github.com/t0thkr1s/allsafe |
144 | 155 | - [ ] https://github.com/oversecured/ovaa |
|
0 commit comments